Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-3024

Опубликовано: 31 авг. 2009
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3

Описание

The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which allows remote attackers to bypass the hostname check for a certificate.

РелизСтатусПримечание
dapper

not-affected

devel

not-affected

1.27-1
hardy

not-affected

intrepid

not-affected

1.13-1
jaunty

ignored

end of life
karmic

not-affected

1.27-1
lucid

not-affected

1.27-1
maverick

not-affected

1.27-1
upstream

released

1.27-1

Показывать по

Ссылки на источники

EPSS

Процентиль: 43%
0.00202
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 16 лет назад

The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which allows remote attackers to bypass the hostname check for a certificate.

nvd
больше 16 лет назад

The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which allows remote attackers to bypass the hostname check for a certificate.

debian
больше 16 лет назад

The verify_hostname_of_cert function in the certificate checking featu ...

github
больше 3 лет назад

The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which allows remote attackers to bypass the hostname check for a certificate.

EPSS

Процентиль: 43%
0.00202
Низкий

4.3 Medium

CVSS2